CVE-2026-63730

MEDIUM

HyperDX < 2.31.0 SSRF via Webhook Test Endpoint

Title source: cna
STIX 2.1

Description

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can bypass the insufficient hostname blacklist validation in the webhook handler to enumerate internal services, interact with internal containers, or access cloud instance metadata services including provider metadata endpoints.

References (5)

Core 5
Core References
Exploit technical-description exploit issue-tracking
Researcher Disclosure
https://github.com/hyperdxio/hyperdx/issues/2588
Release Notes patch release-notes
Release Notes
https://github.com/hyperdxio/hyperdx/releases/tag/%40hyperdx%2Fapp%402.31.0
Issue Tracking issue-tracking patch
Pull Request
https://github.com/hyperdxio/hyperdx/pull/2593

Scores

CVSS v3 5.0
EPSS 0.0023
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
hyperdxio/hyperdx 2.0.0 - 2.31.0
Published Jul 20, 2026
Tracked Since Jul 21, 2026